200-201 Security Concepts Practice Question
A security team is designing a defense-in-depth strategy. They want to add a control that inspects the actual content of network traffic for known attack signatures and can block or alert on malicious payloads in real time. Which technology best meets this requirement?
⚠ Common exam trap
Many exam-takers confuse detection with prevention; an IDS detects but does not block, while an IPS both detects and blocks inline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Intrusion prevention system (IPS)
An IPS is designed for inline deep packet inspection, matching traffic against signatures and behavioral rules and taking action to block or alert. Because it sits in the traffic path, it can stop attacks in real time, unlike passive detection or simple filtering controls. This makes it the best fit for content inspection with active response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Intrusion prevention system (IPS)
Why this is correct
An IPS inspects packet payloads against signatures and behavioral rules and can actively block or drop malicious traffic in real time. It is placed inline in the traffic path, so it can prevent attacks rather than just detect them. For content inspection with blocking capability, an IPS is the appropriate control.
- ✗
Virtual private network (VPN) concentrator
Why it's wrong here
A VPN concentrator establishes encrypted tunnels for remote access or site-to-site connectivity. Its primary role is confidentiality and secure transport, not content inspection. While it may enforce some access policies, it does not analyze packet payloads for attack signatures or block malicious content.
- ✗
Load balancer
Why it's wrong here
A load balancer distributes incoming traffic across multiple servers to improve availability and performance. It may perform health checks and some Layer 7 routing, but it is not designed to inspect payloads for attack signatures or to block malicious traffic. It does not provide intrusion prevention functionality.
- ✗
Host-based firewall
Why it's wrong here
A host-based firewall filters traffic based on IP addresses, ports, and protocols on a single endpoint. It does not inspect payload content for attack signatures, so it cannot identify or block malicious payloads based on known attack patterns. It lacks the deep packet inspection and signature database an IPS provides.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.